3 ms·
First thing that comes to mind is tracing system calls with strace (linux), truss (bsd), or Dtrace (recommended). A common probability theory such as Markov Ch
by jradd 9y ago
First thing that comes to mind is tracing system calls with strace (linux), truss (bsd), or Dtrace (recommended).
A common probability theory such as Markov Chains could be used as a reference:
Markov Chains
http://cucis.ece.northwestern.edu/projects/DMS/publications/AnomalyDetection.pdf http://cucis.ece.northwestern.edu/projects/DMS/publications/...
There is no limit of items this model could be applied to, but a few that come to mind; given the context might be;
Load Generation or emulation at the filesystem, network or application level.
iowait, vmstats, memory leaks (Why am I unable to account for N percent memory), Cache hit vs miss,
Network stats, heuristics, buffer overflows, denial of service (listen/accept queue overflow), TCP RTT, NTP Jitter, Response Time, etc…